(21) Upon assessing the impact of a cyber incident, a communications undertaking takes into account in particular the following, where such information is available: 1) the estimated number of users affected by the cyber incident; 2) the duration of the cyber incident; 3) the geographical spread of the area affected by the cyber incident; 4) the extent to which the functioning of the networks and services are affected; 5) the extent of impact on economic and societal activities. [RT I, 15.12.2021, 1 – entry into force 01.02.2022] (3) If necessary, the Information System Authority reports the cyber incidents specified in subsection 2 of this section to foreign supervision authorities and the European Network and Information Security Agency (ENISA). If the Information System Authority finds that due to public interest it is justified to make the violation public, it may inform the public thereof or require the communications undertaking to do it. [RT I, 15.12.2021, 1 – entry into force 01.02.2022] (4) The Estonian Information System Authority shall submit a summary report on the notices submitted pursuant to subsection 2 of this section and on measures applied to the European Commission and ENISA once per calendar year. [RT I, 13.03.2014, 4 – entry into force 01.07.2014] (5) The Estonian Information System Authority is entitled to require a communications undertaking to: [RT I, 13.03.2014, 4 – entry into force 01.07.2014] 1) provide information needed to assess the security and integrity of their communications services and networks, including security policies; 2) order a security audit carried out by a qualified independent body or a competent national authority and make the results thereof available to the Estonian Information System Authority. The cost of the audit shall be covered by the communications undertaking. [RT I, 13.03.2014, 4 – entry into force 01.07.2014] (6) Instead of the requirements provided in subsections 1–5 of this section, the requirements provided in and established on the basis of §§ 7 and 8 of the Cybersecurity Act apply to the communications undertakings providing vital services, cable distribution services consumed by no less than 10,000 end-users, or broadcasting network services. [RT I, 22.05.2018, 1 – entry into force 23.05.2018] § 873. Requirements for communications networks and services to ensure national security (1) The hardware and software used in provision of communications services in a communications network must not pose a risk to national security. (2) The hardware and software used in provision of communications services in a communications network may pose a risk to national security due to: 1) a high risk arising from its producer or provider of maintenance or support services (hereinafter high risk hardware or software); 2) a risk arising from the technical characteristics or configuration of the hardware or software. (3) Upon assessing high risk hardware or software, account is taken, among other things, of information on whether: 1) the producer or provider of maintenance or support services has its registered office or head office in a country (hereinafter country of domicile), which is not a member state of the European Union, the North Atlantic Treaty Organisation (hereinafter NATO) or the Organisation for Economic Co-operation and Development (hereinafter OECD); 2) the principles of democratic rule of law are not observed or human rights are not respected in the country of domicile of the producer or provider of maintenance or support services; 3) the intellectual property, personal data or business secrets of persons of other countries are not protected in the country of domicile of the producer or provider of maintenance or support services; 4) the country of domicile of the producer or provider of maintenance or support services exhibits aggressive behaviour in cyberspace; 5) the member states of the European Union, NATO or OECD have attributed cyber-attacks to the country of domicile of the producer or provider of maintenance or support services; 6) the producer or provider of maintenance or support services is subjected to the government or state authority of the country of domicile or other foreign country that has no independent judicial control; 7) the country of domicile of the producer or provider of maintenance or support services or another foreign country may oblige it to act in a manner posing a risk to the national security of Estonia; 8) the economic activities of the producer or provider of maintenance or support services are not based on market-based competition or no adequate conditions have been created for this in the country of domicile; 9) the ownership structure, organisational structure or management structure of the producer or provider of maintenance or support services is not transparent; 10) financing of the producer or provider of maintenance or support services is not transparent; 11) the products or services of the producer or provider of maintenance or support services include vulnerabilities and no adequate security measures have been implemented to eliminate these; Page 50 / 89 Electronic Communications Act

Select target paragraph3